Data Processing Agreement
Template -- Requirement I.20 of specs/security-and-data-protection-hardening.md
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the agreement between [Aicentic, Inc. -- legal entity name] ("Processor", "we", "us") and the customer identified in the applicable order form or account ("Controller", "you"), and governs Aicentic's processing of personal data on your behalf when you use the Service.
2. Subject matter and duration
Processor processes personal data on Controller's behalf for the duration of the underlying subscription agreement, for the purpose of providing the Service (operating AI agents, storing and retrieving agent knowledge-base content, and delivering conversation/lead data back to Controller).
3. Categories of data and data subjects
Data subjects: Controller's end users/website visitors who interact with Controller's agent, and Controller's own team members who use the dashboard.
Categories of personal data: names, email addresses, and any other information a visitor voluntarily provides in a conversation or lead-capture form; Controller team members' account/contact information; content Controller uploads to train its agents (which may itself contain personal data Controller is responsible for having a lawful basis to process).
4. Processor's obligations
- Process personal data only on Controller's documented instructions (including via the Service's own configuration), unless required otherwise by law;
- Ensure personnel with access to personal data are bound by confidentiality;
- Implement the technical and organizational security measures described in section 6;
- Assist Controller in responding to data subject rights requests (access, deletion, export) and in meeting its own breach-notification obligations;
- Delete or return personal data at the end of the engagement, per the retention terms in our Data Retention Policy;
- Make available the information reasonably necessary to demonstrate compliance with this DPA.
5. Sub-processors
Controller consents to Processor engaging the sub-processors listed below to help deliver the Service, each bound by a data processing agreement offering an equivalent level of protection. Processor will give Controller reasonable notice before adding a new sub-processor, allowing Controller to object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| [VPS/hosting provider] | Application hosting, database storage | [Region] |
| OpenAI / Anthropic / Google / Mistral / Groq (as configured per agent) | Generating agent responses from conversation content | United States (varies by provider) |
| Paddle.com Market Ltd | Payment processing, billing | United Kingdom |
| [Transactional email provider] | Account/notification emails | [Region] |
| [Off-site backup storage provider, once provisioned] | Encrypted off-site database backup storage | [Region] |
Bracketed rows are placeholders for infrastructure decisions not yet finalized (see this document's callout above) -- fill in the real provider/region before publishing, and keep this table in sync whenever a sub-processor changes.
6. Security measures
Processor maintains technical and organizational measures appropriate to the risk, including: encryption of data in transit (TLS) and at rest for backups; role-based access control and audit logging; tenant data isolation enforced at the application and database-query layer; regular dependency vulnerability scanning; and encrypted, access-controlled database backups. See our Privacy Policy for further detail.
7. Data subject requests and breach notification
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller's data, and will provide reasonable assistance with Controller's own notification obligations. Requests from data subjects received directly by Processor will be forwarded to Controller promptly.
8. International transfers
Where personal data is transferred outside the data subject's jurisdiction (e.g. to a sub-processor listed in section 5), Processor relies on an appropriate transfer mechanism -- such as the EU Standard Contractual Clauses -- where legally required. [Counsel to confirm the specific mechanism(s) applicable given your actual sub-processor locations before this is relied upon.]
9. Audits
Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, conducted by Controller or an auditor mandated by Controller, subject to reasonable notice and confidentiality.
10. Contact
Questions about this DPA, or to request an executable/countersigned copy, can be sent to info@aicentic.com.